
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

Checks projects for compromised packages, suspicious files, and import statements.

Cryptanalysis of a proprietary 1999 video DRM system. Recovers 61 encrypted wrestling videos from the WCW Internet Powerdisk CD-ROM through static…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Detailed analysis of CVE-2025-61686, a path traversal vulnerability in React Router's file session storage, including root cause, attack scenarios,…

**HashEye** is a powerful Python CLI tool for instantly detecting and analyzing hash types. It provides detailed information about hash formats,…

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS),…

Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness

Stop prompt injection attacks before they reach your LLM — zero API costs, runs entirely locally, integrates in 2 minutes. Prompt injection is the…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Protection against Model Serialization Attacks

Anti-LLM obfuscation via finger counting

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

A malware analysis and classification tool.